Bot Blocker Index
Bot protection is expensive, and the headline numbers are effectively unverifiable — DataDome markets “99.99% detection accuracy”. This index compares each vendor’s claim against reproducible tests on surfaces they invite us to use, anonymized real-world challenge rates, and published research.
What is a bot blocker?
A bot blocker is software or a service that detects automated, non-human traffic and blocks, challenges, or rate-limits it — usually as a WAF bot-management product, a CAPTCHA or challenge widget, or device/TLS fingerprinting built into one of those.
This index tracks named bot-blocker products and compares each vendor's marketed claim against our own reproducible tests and anonymized real-world measurements.
How do bot blockers detect bots?
Detection is layered. Our technique taxonomy groups it into network identity (IP-reputation / ASN scoring), TLS / HTTP fingerprinting (JA3/JA4 handshake and HTTP/2 frame-order mismatches), browser hardening checks (headless/automation tells such as navigator.webdriver and CDP), behavioral simulation (mouse, dwell, and scroll scoring), challenge handling (the CAPTCHA layer), and client interrogation replay (active environment probes, Kasada-style).
Most vendors combine several of these layers rather than relying on just one.
Which bot blockers does this index track?
This index currently tracks 16 bot-mitigation vendors and products, across full-suite platforms, CDN-bundled bot managers, CAPTCHA/challenge providers, and fingerprinting vendors: DataDome, HUMAN Security, Cloudflare Bot Management, Cloudflare Turnstile, Cloudflare Bot Fight Mode, Akamai Bot Manager, AWS WAF Bot Control, Fastly Bot Management, Netacea, Imperva Advanced Bot Protection, Kasada, F5 / Shape Security, Arkose Labs, Google reCAPTCHA (v3 / Enterprise), hCaptcha, Fingerprint (FingerprintJS).
Each vendor page carries its marketed claim (where captured) against our own test results and any passive measurement.
How is each bot blocker tested?
Every number on this site comes from one of three sources, detailed on our methodology page: reproducible bypass attempts run only against surfaces a vendor invites testing on, or against our own trial/free-tier deployments; passive measurement of whether a single honest, default automated client is served, challenged, or hard-blocked by a live site; or bypass rates cited from existing published research.
We never bypass a security control on a non-consenting third party's production system, and we never name a vendor's paying customer.
- 16 bot-mitigation vendors are tracked — see the full list.
- DataDome markets its product as “Leverage 1000s of AI models for 99.99% detection accuracy” — captured 2026-08-01 from DataDome’s own site.
- Scrapfly, a commercial bypass-API vendor, self-reports a 96% bypass rate against DataDome — see the source; this is the other side of the market’s own marketing, not independently verified.
- Passive challenge-rate data across the index was last measured 2026-09-26 — see methodology.
| Vendor | Category | Claim | Challenged a default bot | Claim vs. reality |
|---|---|---|---|---|
| Arkose Labs | captcha | — | — | not yet scored |
| Cloudflare Turnstile Cloudflare | captcha | — | — | 60/100 |
| Google reCAPTCHA (v3 / Enterprise) Google | captcha | — | — | 45/100 |
| hCaptcha Intuition Machines | captcha | — | — | 58/100 |
| AWS WAF Bot Control Amazon (AWS) | cdn-bot-manager | — | — | not yet scored |
| Akamai Bot Manager Akamai | cdn-bot-manager | — | 0.0% of 40 | not yet scored |
| Cloudflare Bot Fight Mode Cloudflare | cdn-bot-manager | — | — | 72/100 |
| Cloudflare Bot Management Cloudflare | cdn-bot-manager | — | 43.2% of 44 | not yet scored |
| Fastly Bot Management Fastly (absorbed Signal Sciences) | cdn-bot-manager | — | — | not yet scored |
| Kasada | cdn-bot-manager | — | 100.0% of 1* | not yet scored |
| Fingerprint (FingerprintJS) | fingerprint | — | — | 55/100 |
| DataDome | full-suite | 99.99% | 87.5% of 8 | not yet scored |
| F5 / Shape Security F5 | full-suite | — | 50.0% of 2* | not yet scored |
| HUMAN Security HUMAN (absorbed PerimeterX + White Ops) | full-suite | — | 50.0% of 2* | not yet scored |
| Imperva Advanced Bot Protection Thales (absorbed Distil Networks) | full-suite | — | 66.7% of 3 | not yet scored |
| Netacea | full-suite | — | — | not yet scored |
“Challenged a default bot” is a passive observation: a vanilla automated client requested each site’s public homepage; we record whether it was challenged. No bypass, no login, no content stored — see methodology.
* sample too small (n<3) to be reliable — shown for completeness only.
Passive data last measured 2026-09-26 (5d ago).
Vendor claims are not fixed — they get tightened, softened, and sometimes removed. We read monthly Wayback snapshots of each vendor’s own marketing pages and publish a number only where an archived snapshot carries it and the sentence around it was reviewed and judged to be the vendor describing its own product — not a customer case study, an uptime SLA, or a traffic-composition stat. Nothing is inferred between two snapshots.
- Fingerprint (FingerprintJS) — 99.5% detection accuracy: archived Nov 2019 to Dec 2024; 1 captured month inside that span carried no such claim; not on the tracked pages in the 20 captured months since
- Netacea — 0.001% false-positive rate: archived Apr 2021 to Mar 2026; first archived as 0.0001%
- DataDome — 2ms edge mitigation latency: archived Jan 2019 to Aug 2026; first archived as 5ms; 35 captured months inside that span carried no such claim
- DataDome — 99.99% detection accuracy: archived Jan 2023 to Aug 2026; 12 captured months inside that span carried no such claim
- DataDome — 0.01% false-positive rate: archived Jan 2023 to Aug 2026; 17 captured months inside that span carried no such claim
- Cloudflare Bot Management — 0.3ms decision latency: archived Mar 2022 to May 2023; not on the tracked pages in the 3 captured months since
- DataDome — 50ms detection-engine adaptation latency: archived Dec 2023 to Apr 2026; not on the tracked pages in the 4 captured months since
A bit — but less than you’d think at the homepage level. Across the same sites, a default bot from a datacenter is stopped only a few points more often than from a residential IP; a plain homepage request rarely trips the heavy challenge, so IP reputation barely moves it here. The vivid exception is challenge-on-demand products — Cloudflare Bot Fight Mode blocked our datacenter request outright (403) but served every residential client. Network identity is a real lever; how big depends on the product.